Security Advisory

CVE-2017-7719

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-04-12 15:00:00
Last updated 2024-08-05 16:12:28
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.